Subscribe Sign in

Meta Muse AI app flaw lets local malware redirect dictation traffic

1 min read Rewritten in plain language

Artificial intelligence

Show what we removed Rules applied: A3×4 C2 D2×3 D3×12 D4 F2×4 all 30 rules
  • Ad biz promises users control while bug could expose voice prompts.
  • The flaw could enable prompt injection, the theft of authentication material, and abuse of whatever access the user has granted to Muse.
  • In a phone interview with The Register, Wardle likened the situation to living in an apartment building.
  • Wardle added that Apple provides on-device local dictation and if Meta chose to use that API, this vulnerability would not exist.

4 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Security researcher Patrick Wardle, founder of nonprofit Objective-See, has devised a proof-of-concept called not-a-mused for what he describes as a local zero-day in the Muse macOS app that allows.

The report’s most important sentence, shortened and in plain words. How

Headline check

The one thing this headline claims is in the report.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. One claim in this headline could be checked, so this is a narrow pass and not a thorough one. How this is checked

Ad biz promises users control while bug could expose voice prompts.

Meta made much of the security of its AI assistant app Muse at launch earlier this month, calling out the app's reliance on Muse Secure VM.

"Each person stays in control of their Muse and decides how much access it gets," the ad biz declared, echoing earlier expansive claims about the privacy of its data gathering business.

Security researcher Patrick Wardle, founder of nonprofit Objective-See, has devised a proof-of-concept called not-a-mused for what he describes as a local zero-day in the Muse macOS app that allows an unprivileged local process to redirect Muse's dictation traffic and potentially abuse access granted to the app.

Muse, he explains in the project repo, has an undocumented setting called endo_voyager_dictation_endpoint that an attacker running code locally can change without special privileges to redirect dictation traffic to an attacker-controlled endpoint, potentially exposing dictated audio and prompts sent to the backend AI model. The flaw could enable prompt injection, the theft of authentication material, and abuse of whatever access the user has granted to Muse.

The vulnerability is not an issue for a remote attacker.

In a phone interview with The Register, Wardle likened the situation to living in an apartment building.

Apple, said Wardle, has done a good job with its Transparency, Consent, and Control framework and with privilege separation.

Wardle added that Apple provides on-device local dictation and if Meta chose to use that API, this vulnerability would not exist.

Shortened to 1 minute of reading, this version reads 6.8 on the Niral Score.

You are reading our version, not theirs. This is The Register's report shortened to its most important sentences, in plainer words, with verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 9.2 9 74 -0.1 32.2
Mundane Readneutralized from The Register 7.3 9 74 -0.1 32.2

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works